cmux-terminal-multiplexer

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the usage of cmux, a terminal and browser automation utility. No malicious patterns, obfuscation, or unauthorized data exfiltration were detected. The skill focuses on legitimate productivity and automation features.- [COMMAND_EXECUTION]: The skill uses cmux send-surface to execute commands in terminal splits and utilizes python3 for parsing JSON output. These are standard operations for the tool's intended purpose of terminal management and automation.- [DATA_EXFILTRATION]: While the skill can read terminal output and browser state (including cookies and session data), these are documented features necessary for its operation. There are no instructions to send this data to unauthorized external locations.- [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from terminal panes and web pages. While this creates a surface for indirect prompt injection from untrusted sources, the skill documentation does not contain any instructions to bypass safety filters or override agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 03:55 AM